# Microsoft NTLM Deprecation - Three-Stage Phase-Out Plan

> Microsoft's three-stage NTLM deprecation plan: enterprise migration timeline from NTLM to Kerberos/Negotiate, legacy application compatibility matrix, and the operational risk of a 30-year protocol phase-out across millions of Active Directory environments.

- **Published:** 2026-02-03T02:10:00Z
- **Last reviewed:** 2026-02-03T02:10:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0040
- **ID:** TL-2026-0040
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** MONITORING
- **Detections:** 15 · **IOCs:** 40 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Microsoft announced the formal deprecation of NTLM authentication in June 2024 with a phased three-stage approach to remove the protocol from Windows. This threat covers the ENTERPRISE MIGRATION perspective — distinct from TL-0018 (NTLM enforcement and the attack surface). Stage 1 (Audit & Discovery, 2024-2025): Organizations enable NTLM auditing via Group Policy (Network Security: Restrict NTLM: Audit NTLM authentication in this domain / Audit Incoming NTLM Traffic) to discover all applications, services, and systems still using NTLM. Windows Event IDs 8001-8004 log NTLM usage. This phase reveals the true scope of NTLM dependency — most enterprises discover 10-40% of authentication traffic is still NTLM. Stage 2 (Selective Restriction, 2025-2026): Organizations begin blocking NTLM for specific applications and services using NTLM restriction policies (Network Security: Restrict NTLM: NTLM authentication in this domain / Add server exceptions). Server-side and client-side exceptions manage compatibility. IAM Credential Roaming exceptions handle legacy device authentication. This phase exposes the COMPATIBILITY MATRIX problem: legacy applications (pre-2010 LOB apps, older ERP systems, embedded devices, legacy printers, cross-forest trusts, non-Windows clients) that cannot negotiate Kerberos. Stage 3 (Full Deprecation, 2026+): Microsoft removes NTLM components from Windows. NTLMv1 removed first (immediate security gain — NTLMv1 hashes are crackable in seconds). NTLMv2 removal follows (harder — NTLMv2 is still cryptographically weak but some services have no Kerberos path). The compatibility matrix is the critical challenge: (1) Legacy LOB applications: custom-built .NET/COM applications using NTLM directly via SSPI rather than Negotiate. Many have hardcoded NTLM providers. Remediation: code modification or wrapper. (2) Cross-forest trusts: NTLM is required for some cross-forest authentication scenarios where Kerberos trust paths don't exist. Remediation: establish Kerberos forest trusts or migrate to Azure AD/Entra ID. (3) Non-Windows clients: Linux/macOS clients using NTLM for SMB/CIFS access. Remediation: configure Kerberos on non-Windows clients (krb5.conf + keytab). (4) Embedded devices: printers, scanners, ICS/OT devices with hardcoded NTLM. Remediation: network segmentation + service accounts with NTLM exceptions. (5) Older SQL Server instances: pre-2016 SQL Server using NTLM for Windows authentication. Remediation: upgrade or configure SPN for Kerberos. (6) Web applications using Windows Integrated Authentication (WIA) with NTLM fallback: IIS sites configured for NTLM rather than Negotiate. Remediation: change IIS authentication provider order. The migration risk is operational disruption: blocking NTLM without completing the compatibility audit causes authentication failures that break production applications, prevent users from accessing file shares, and disrupt cross-domain trust relationships. The security risk of NOT migrating: NTLM relay attacks (ntlmrelayx), pass-the-hash, reflection attacks, and credential theft via LLMNR/NBT-NS poisoning remain the #1 Active Directory attack surface. Every day NTLM remains enabled is another day attackers can relay, capture, and crack NTLM hashes.

## MITRE ATT&CK

- T1003.003 NTDS
- T1550.002 Pass the Hash
- T1557.001 Name Resolution Poisoning and SMB Relay
- T1557 Adversary-in-the-Middle
- T1003 OS Credential Dumping
- T1649 Steal or Forge Authentication Certificates
- T1187 Forced Authentication
- T1550 Use Alternate Authentication Material
- T1021 Remote Services
- T1078 Valid Accounts
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1190 Exploit Public-Facing Application
- T1588 Obtain Capabilities
- T1047 Windows Management Instrumentation
- T1110 Brute Force
- T1040 Network Sniffing
- T1098 Account Manipulation
- T1548 Abuse Elevation Control Mechanism

## Sources

- [The Hacker News: Microsoft Begins NTLM Phase-Out With Three-Stage Plan](https://thehackernews.com/2026/02/microsoft-begins-ntlm-phase-out-with.html)
- [Microsoft Security Blog: NTLM Deprecation](https://techcommunity.microsoft.com/)
- [Microsoft: NTLM Overview — Windows Server](https://learn.microsoft.com/en-us/windows-server/security/kerberos/ntlm-overview)
- [Microsoft: NTLM Deprecation — Windows IT Pro Blog](https://techcommunity.microsoft.com/blog/windows-itpro-blog/the-evolution-of-windows-authentication/4478292)
- [Microsoft: Restrict NTLM GPO Settings](https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/network-security-restrict-ntlm-ntlm-authentication-in-this-domain)
- [Microsoft: Kerberos Authentication Overview](https://learn.microsoft.com/en-us/windows-server/security/kerberos/kerberos-authentication-overview)
- [Microsoft: Windows Server 2025 Features](https://learn.microsoft.com/en-us/windows-server/get-started/whats-new-windows-server-2025)
- [MITRE ATT&CK: NTLM Relay T1557.001](https://attack.mitre.org/techniques/T1557/001/)
- [MITRE ATT&CK: Pass the Hash T1550.002](https://attack.mitre.org/techniques/T1550/002/)
- [Impacket ntlmrelayx](https://github.com/fortra/impacket/blob/master/examples/ntlmrelayx.py)
- [Responder — LLMNR/NBT-NS Poisoner](https://github.com/lgandx/Responder)
- [PetitPotam — CVE-2021-36942](https://github.com/topotam/PetitPotam)
- [DFSCoerce — MS-DFSNM Coercion](https://github.com/Wh04m1001/DFSCoerce)
- [CVE-2023-23397: Outlook NTLM Hash Leak](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23397)
- [CIS Microsoft Windows Server Benchmark](https://www.cisecurity.org/benchmark/microsoft_windows_server)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0040
